CVE Tools

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

The Hacker NewsBy The Hacker News

Reported exploitedCisco Secure Firewall Management Center (FMC)Citrix NetScaler ADC

Our summary

CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, imposing a mandatory remediation deadline of September 12, 2026, for federal civilian executive branch agencies. The flagged defects include a critical authentication bypass in Cisco Secure Firewall Management Center (CVE-2026-20079), an authentication bypass in Citrix NetScaler ADC (CVE-2026-19490), and a heap-based buffer overflow in Fortinet FortiOS (CVE-2025-25249). These additions follow recent reports of active exploitation, including state-sponsored espionage against Cisco routers and a Russian-linked campaign using the Fortinet flaw to deploy the PivotC2 remote access trojan.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store